Port 12345NetBus / NetBuster
Port 12345 is strongly associated with the NetBus remote administration tool, which is widely known as a backdoor Trojan horse. It was originally designed for legitimate remote control but was quickly adopted by malicious actors for unauthorized access and control over infected machines. Additionally, this port has seen use by NetBuster, a NetBus honeypot tool, and is sometimes used by certain networked games such as Little Fighter 2..
- transport
- unknown
- in transit
- cleartext
- assignment
- unofficial
- risk
- 4/10
- lookups
- 19,893
single transport
payload readable on path
used by convention
caution
rank 126 of 993 · top 13%
Technical Details
what runs on :12345Port 12345 historically became infamous due to its association with NetBus, a Windows-based remote administration tool released in the late 1990s. The software includes a server component, which runs on the target machine and listens by default on TCP port 12345, awaiting connections from the client's control software. The tool allows remote interaction, screen control, file system access, keystroke logging, and more, making it both a potent utility and a dangerous Trojan horse if deployed surreptitiously.
Unlike legitimate administration software like VNC or RDP, NetBus was widely abused as a backdoor, often installed unknowingly to the victim, giving attackers unfettered access without explicit permission. Because of its default port, 12345 became synonymous with suspicious or malicious remote access activity.
In response, some security researchers developed tools such as NetBuster, which acts as a honeypot by simulating a NetBus server on port 12345, to catch or log intrusion attempts. The port also has incidental, benign uses, notably by the game Little Fighter 2. However, these are far less common and the port typically raises red flags in network security contexts.
Security Information
exposure of :12345risk score
4/ 10caution
worth attention. how exposed you are depends on configuration — don't leave it reachable from the internet without a reason.
security averages 3.8 across 216 ports — this one sits 0.2 above.
in transit
cleartext
credentials and payloads are readable by anyone on path
assignment
unofficial
used by convention, not registered — what answers here varies by deployment
reachable over
unknown
every listening transport is another surface to filter at the edge
security overview
Common vulnerabilities:
- Unauthorized remote control if NetBus or similar Trojans infect a machine.
- Credential theft through keylogging or screen monitoring once the attacker has connected.
- Lateral movement by attackers leveraging the backdoor to install further malware.
- Port scans to detect open 12345 often indicate reconnaissance activity by threat actors.
Common mitigations:
- Block inbound and outbound traffic on port 12345 at network perimeters unless explicitly required.
- Run antivirus and anti-malware solutions capable of detecting NetBus or similar threats.
- Use intrusion detection and honeypot strategies (like NetBuster) to monitor suspicious activity.
- Regularly audit open ports and running services on systems to ensure unauthorized software is not operating.
- Educate users about social engineering and malware to reduce initial infection risks.
Related Ports
the 8 most looked-up other ports in security — 216 ports carry that label.
| port | service | risk | |||
|---|---|---|---|---|---|
| :8881 | Atlasz Secure Server | TCP | Web Services | caution | 67.6k |
| :443 | HTTPS | TCPtls | Web Services | caution | 65.9k |
| :8291 | Winbox MikroTik Admin | TCP | Security | caution | 62.9k |
| :3268 | Microsoft Global Catalog (GC) | TCPUDP | Security | caution | 54.6k |
| :135 | Microsoft EPMAP | TCPUDP | Security | caution | 51.9k |
| :3128 | Squid Proxy HTTP | TCP | Web Services | caution | 45.8k |
| :8080 | HTTP Alternate | TCPtls | Web Services | caution | 44.9k |
| :7000 | Vuze HTTPS Tracker | TCPtls | Security | caution | 28.9k |
risk mix of the 8 listed
- caution100%
3 of 8 encrypted